About the role
About Sift
Sift is the data infrastructure platform for hardware engineering teams. We turn high-frequency telemetry into engineering insights for mission-critical machines: rockets, satellites, autonomous vehicles, energy systems, and defense platforms. Founded by former SpaceX engineers, we are building the review and analysis layer for the AI era of physical systems.
In This Role, You’ll:
Secure-by-default guardrails: Build the patterns, libraries, and secure-by-default standards (authentication, authorization, input handling, cryptography) that make whole classes of vulnerabilities hard to introduce, and review Go and Rust for security.
Threat modeling and secure design: Partner with engineering teams on new features and architectural changes across a distributed, polyglot system, and turn the results into concrete design decisions.
Software supply chain: Own dependency integrity, artifact signing, and build-pipeline trust. This matters especially for the self-managed and air-gapped deployments our customers run.
Developer-facing security tooling: Extend the app sec toolchain in CI/CD — SAST, software composition analysis, secret scanning, and fuzzing — and keep it high-signal, tuning it so findings are accurate and actionable for developers rather than noise. Partner with the owning teams to drive real risks to remediation.
Raise engineering's security fluency: Through design reviews, documentation, and direct collaboration, help the whole org build securely by default.
The Skillset You’ll Bring:
5+ years building production software, including hands-on security ownership of a real codebase. You are a software engineer first, applying that skill to security.
Ability to read and review either Go and/or Rust with fluency. You don't need to have shipped both, but you should be able to reason about security in our stack from day one.
Strong grounding in application security fundamentals: web and API vulnerability classes, authentication and authorization patterns, and applied cryptography.
Experience with threat modeling and secure design review on non-trivial, distributed systems.
Hands-on experience embedding security tooling (SAST, SCA, secret scanning) into developer workflows and CI/CD; tuning it for signal over noise.
A bias toward building and shipping solutions that scale across teams, and toward driving their adoption. Comfortable picking up an existing security baseline and pushing it forward rather than needing to start from zero.
Clear communication with engineers and leadership. You can explain risk and tradeoffs to people who don't live in security.
Bonus Points:
Experience securing software that ships to customer-controlled, on-premise, or air-gapped environments.
Familiarity with software supply chain tooling and standards (Sigstore, SLSA, SBOM generation).
Background with Rust memory-safety considerations, or with fuzzing native and high-throughput data paths.
Container image and build-time security (image scanning, minimal/hardened base images).
Familiarity with DAST or dynamic testing approaches.
Exposure to regulated environments (defense, aerospace, or similar).
Location:
SIFT’s headquarters is in Marina Del Rey, CA (Next to LAX). We collaborate in person twice a week—on Mondays and Thursdays—and come together for a full week every two months. We are open to relocating candidates to LA or working from our San Francisco office for the right candidate.
Salary range: $180,000 - $230,000 per year. Plus equity and benefits.
Eligibility:
U.S. Citizenship Required: This position requires U.S. citizenship due to the nature of certain customer environments, security requirements, and access obligations associated with the role.
Aplyr's read
Sift leverages machine learning to combat fraud, attracting tech-savvy professionals passionate about security and risk management.
What's promising
- •Sift's machine learning technology is at the forefront of fraud prevention.
- •The company offers diverse roles, from AI to strategic operations, for career growth.
- •Sift's solutions help businesses proactively manage and reduce fraudulent activities.
What to watch
- •The niche focus on fraud prevention may limit broader market opportunities.
- •Rapid tech changes require constant adaptation, posing challenges for employees.
- •The competitive landscape in fraud prevention technology is intense.
Why SIFT
- •Sift specializes in machine learning for risk management, a distinct niche.
- •The company integrates cutting-edge AI to enhance fraud detection accuracy.
- •Sift's focus on proactive fraud solutions differentiates it from reactive competitors.
Aplyr’s read is generated by AI from public sources. Was it useful?
About SIFT
Sift is a technology company that provides machine learning solutions for fraud prevention and risk management, helping businesses to analyze and mitigate fraudulent activities.
Similar roles
Senior Product Security Engineer
Anduril Industries
Product Security Engineer, Programs
Anduril Industries
Product Security Engineer, Programs
Anduril Industries
Product Security Engineer, Programs
Anduril Industries
Senior Product Security Engineer (Active Clearance)
Anduril Industries
Product Security Engineer
Modern Health